SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

39,286 results · page 115 of 786

CVESummaryPriorityPublished
CVE-2026-27851When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped.CRITICAL 9.1EPSS 0.41%12 May 2026
CVE-2026-8072Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board.CRITICAL 9.2EPSS 0.15%12 May 2026
CVE-2026-7428Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative…CRITICAL 9.2EPSS 0.24%12 May 2026
CVE-2026-41551A vulnerability has been identified in ROS# (All versions < V2.2.2).CRITICAL 9.3EPSS 0.49%12 May 2026
CVE-2026-25787This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page.CRITICAL 9.3EPSS 0.37%12 May 2026
CVE-2026-25786This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page.CRITICAL 9.3EPSS 0.37%12 May 2026
CVE-2025-6577Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd.CRITICAL 9.8EPSS 0.26%12 May 2026
CVE-2026-41872"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation.CRITICAL 9.1EPSS 0.16%12 May 2026
CVE-2026-34263Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and…CRITICAL 9.6EPSS 0.61%12 May 2026
CVE-2026-34260SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input.CRITICAL 9.6EPSS 0.47%12 May 2026
CVE-2026-45321TanStack Unspecified VulnerabilityKEVCRITICAL 9.6EPSS 2.34%12 May 2026
CVE-2026-43914Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled.CRITICAL 9.8EPSS 0.29%11 May 2026
CVE-2026-43900Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine.CRITICAL 9.3EPSS 0.31%11 May 2026
CVE-2026-43899Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE).CRITICAL 9.6EPSS 0.33%11 May 2026
CVE-2026-42882Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler.CRITICAL 9.4EPSS 0.55%11 May 2026
CVE-2026-42869Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example.CRITICAL 10.0EPSS 0.44%11 May 2026
CVE-2026-42864Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]).CRITICAL 9.9EPSS 0.27%11 May 2026
CVE-2026-42858The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter.CRITICAL 9.9EPSS 0.37%11 May 2026
CVE-2026-38567HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints.CRITICAL 9.8EPSS 0.50%11 May 2026
CVE-2026-7813Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.CRITICAL 9.4EPSS 0.46%11 May 2026
CVE-2026-44643Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system.CRITICAL 9.3EPSS 0.48%11 May 2026
CVE-2026-42613Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation.CRITICAL 9.4EPSS 0.94%11 May 2026
CVE-2026-42607Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool.EXPLOITCRITICAL 9.1EPSS 3.94%11 May 2026
CVE-2026-35157Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI.CRITICAL 9.8EPSS 0.32%11 May 2026
CVE-2021-47940WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action.CRITICAL 9.3EPSS 0.40%10 May 2026
CVE-2021-47936OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments.CRITICAL 9.3EPSS 0.66%10 May 2026
CVE-2021-47933WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint.CRITICAL 9.3EPSS 0.59%10 May 2026
CVE-2021-47932WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler.CRITICAL 9.3EPSS 0.40%10 May 2026
CVE-2021-47923OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie.CRITICAL 9.3EPSS 0.42%10 May 2026
CVE-2026-6722As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.CRITICAL 9.5EPSS 0.89%10 May 2026
CVE-2026-42601This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE.CRITICAL 9.3EPSS 0.40%9 May 2026
CVE-2026-42571From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI).CRITICAL 9.0EPSS 0.32%9 May 2026
CVE-2026-42569Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature.CRITICAL 9.4EPSS 1.17%9 May 2026
CVE-2026-42560Any application that trusts token.User.ID as the stable account key can end up mixing or fully merging unrelated Patreon users, which can lead to cross-account access, privilege confusion, and subscription-state leakage.CRITICAL 9.1EPSS 0.42%9 May 2026
CVE-2026-6665A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.CRITICAL 9.8EPSS 0.37%9 May 2026
CVE-2026-44313Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fetchTitleAndHeaders function allows authenticated users to make arbitrary HTTP requests to internal services due to insufficient URL validation that only checks for…CRITICAL 9.1EPSS 0.29%9 May 2026
CVE-2026-42556From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user.CRITICAL 9.0EPSS 0.26%8 May 2026
CVE-2026-42454Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed via ssh2.Client.exec() on remote managed servers without any…CRITICAL 9.9EPSS 0.65%8 May 2026
CVE-2026-42354From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry.CRITICAL 9.8EPSS 0.62%8 May 2026
CVE-2026-42302From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE).CRITICAL 9.8EPSS 0.72%8 May 2026
CVE-2026-42298Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a…CRITICAL 9.8EPSS 0.50%8 May 2026
CVE-2026-42287Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data theft, or system destruction.CRITICAL 10.0EPSS 0.25%8 May 2026
CVE-2026-42193This allows an unauthenticated attacker to spoof SNS events to trigger workflow automations, unsubscribe contacts, manipulate email delivery metrics, and potentially exhaust billing credits.CRITICAL 9.1EPSS 0.13%8 May 2026
CVE-2026-42160Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management.CRITICAL 10.0EPSS 0.25%8 May 2026
CVE-2026-8178Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters.CRITICAL 9.2EPSS 0.57%8 May 2026
CVE-2026-42072Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes.CRITICAL 9.8EPSS 0.44%8 May 2026
CVE-2026-38360Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post()…CRITICAL 9.8EPSS 5.98%8 May 2026
CVE-2026-41070openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows.CRITICAL 10.0EPSS 0.44%8 May 2026
CVE-2026-44498Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops.CRITICAL 9.2EPSS 0.28%8 May 2026
CVE-2026-44497ZEBRA is a Zcash node written entirely in Rust.CRITICAL 9.3EPSS 0.19%8 May 2026

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.